Tavve zoneranger User Manual page 64

Table of Contents

Advertisement

Program Name
Message Search
Cisco Syslog with Max
Severity
Syslog with Max
Severity
Syslog with Facility
If multiple criteria are selected, a Syslog message must match all selected criteria to be forwarded.
Also, syslog filters allow messages to be forwarded as a syslog message or forwarded as an SNMP
trap. If the Cisco Syslog with Max Severity criteria is chosen, the correct Cisco trap for the
severity is generated. Otherwise, a Syslog trap with the specified Specific Type is generated.
NetFlow and sFlow Forwarding
ZoneRanger has the capability to receive NetFlow and sFlow packets from managed devices and
forward those packets through a Ranger Gateway to another application. When a NetFlow or sFlow
packet is received by ZoneRanger, the packet is inspected to determine whether or not to be
syntactically correct. For NetFlow, version 5 and version 9 packets will be verified. For sFlow,
version 4 and version 5 packets will be verified. Any other version will be discarded. If the
NetFlow or sFlow packet is verified to be syntactically correct, it will be processed by the
ZoneRanger forwarding service. Otherwise, the packet is discarded.
Generic UDP Forwarding
ZoneRanger has the capability to receive generic UDP traffic from managed devices and forward
those packets through a Ranger Gateway to another application. Since there is no configured format
for this UDP traffic, no verification occurs before the packets are processed by the ZoneRanger
forwarding service.
ZoneRanger 5.5 User's Guide
Name of the program that generated the
syslog message, as the name appears in
the message.
Search string that the syslog message
must contain. The search string can be a
regular expression search
Cisco syslog messages of the specified
severity or lower.
Note: The severities are more urgent the
lower the number, so this filter
includes the specified severity and
those that are more urgent.
Syslog messages of the specified
severity or lower.
Note: Syslog severities are more urgent
the lower the number, so this filter
includes the specified severity and
those that are more urgent.
Syslog messages of the specified
severity or lower.
Note: Syslog severities are more urgent
the lower the number, so this filter
includes the specified severity and
those that are more urgent.
64

Hide quick links:

Advertisement

Table of Contents
loading

Table of Contents